Showing results for 
Search instead for 
Did you mean: 
Level 7
Report Inappropriate Content
Message 1 of 1

Dashboard False Positive Tuning

My objective is to tune a dashboard that I have created for certain false positive conditions so the events are no longer visible from the view.  For example when using the Normalized Dashboard I want to add a filter to drop events from a certain ip address such as when the destination port is tcp 80.  I can easily add a filter for each of the individual conditions to filter out all events from or port 80, but I am not sure how to filter them out when the combination occurs.  Does anybody know if this is possible?


More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator